Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

System Infected with Virus


  • This topic is locked This topic is locked
33 replies to this topic

#1 rnallamilli

rnallamilli

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 07:08 AM

Hi Team,

 

My Home laptop is infected by Virus. Please help me in fixing this. There are a lot of games which my kid downloaded. May be this is the reason for virus.

 

Thanks,

Raman Nallamilli.



BC AdBot (Login to Remove)

 


#2 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:51 PM

Posted 08 October 2016 - 07:16 AM

Hello rnallamilli and welcome back to the Bleeping Computer forum.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please complete these tasks in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Please download Malwarebytes Anti-Malware to your desktop.

  • double-click mb3-setup-1878.1878-3.4.5.2467.exe and follow the prompts to install the program
  • at the end, be sure a checkmark is placed next to the following
    • Launch Malwarebytes Anti-Malware
    • a 14 day trial of the Premium features is pre-selected: deselect this if you don’t want it, (it won’t diminish the scanning and removal capabilities of the program.
  • click Finish.
  • on the Dashboard, click Update Now
  • after the update completes, click the Scan Now' button.
  • if an update is available, clicking the Update Now button will update it
  • a Threat Scan will begin.
  • when the scan is complete, if malware has been detected, click Apply Actions to allow MBAM to clean what was found
  • when the prompt to restart the computer appears, click Yes.
  • after the restart once you are back at your desktop, open MBAM once more
  • click on the “History” tab, the “Application Logs”
  • double-click on the scan log which shows the date and time of the scan just performed.
  • click Copy to Clipboard
  • please paste the contents of the clipboard into your reply.

Logs to include with the next post:

AdwCleaner log
JRT.txt
Mbam.txt


Thanks

Nina

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#3 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 07:58 AM

Thank you Nina for your quick response. Working on your Action Plan.

 

Thanks,

Raman Nallamilli.



#4 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 08:07 AM

Hi Nina,

 

AdwCleaner Log File :

 

# AdwCleaner v6.021 - Logfile created 08/10/2016 at 18:30:56
# Updated on 06/10/2016 by ToolsLib
# Database : 2016-10-07.1 [Server]
# Operating System : Windows 10 Pro  (X86)
# Username : admin - ADMIN-PC
# Running from : C:\Users\admin\Desktop\adwcleaner_6.021.exe
# Mode: Clean
 
 
 
***** [ Services ] *****
 
[-] Service deleted: LavasoftTcpService
[-] Service deleted: WCAssistantService
 
 
***** [ Folders ] *****
 
[-] Folder deleted: C:\Program Files\bestadblocker
[-] Folder deleted: C:\Program Files\CCuaTThePriice
[-] Folder deleted: C:\Program Files\CutTeHePrice
[-] Folder deleted: C:\Program Files\CutThePrice
[#] Folder deleted on reboot: C:\Program Files\CuttThePrIce
[#] Folder deleted on reboot: C:\Program Files\ExstraaSauvinGGs
[-] Folder deleted: C:\Program Files\ExStrASavings
[#] Folder deleted on reboot: C:\Program Files\ExxstraSaviNgss
[-] Folder deleted: C:\ProgramData\10909700465360421273
[-] Folder deleted: C:\ProgramData\{870d08ad-461d-617e-870d-d08ad46122b5}
[-] Folder deleted: C:\Users\admin\AppData\Roaming\LightningDownloader
[-] Folder deleted: C:\Users\admin\AppData\Roaming\RPEng
[-] Folder deleted: C:\Users\admin\AppData\Roaming\lavasoft\web companion
[-] Folder deleted: C:\ProgramData\IHProtectUpDate
[-] Folder deleted: C:\ProgramData\lavasoft\web companion
[#] Folder deleted on reboot: C:\ProgramData\Application Data\IHProtectUpDate
[#] Folder deleted on reboot: C:\ProgramData\Application Data\lavasoft\web companion
[-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightningDownloader
[#] Folder deleted on reboot: C:\Program Files\ExstraSavings
[-] Folder deleted: C:\Program Files\IncludeRunner
[-] Folder deleted: C:\Program Files\LightningDownloader
[-] Folder deleted: C:\Program Files\lavasoft\web companion
 
 
***** [ Files ] *****
 
[-] File deleted: C:\Users\Public\Desktop\LightningDownloader.lnk
[#] File deleted: C:\WINDOWS\system32\lavasofttcpservice.dll
[-] File deleted: C:\WINDOWS\system32\LavasoftTcpServiceOff.ini
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKCU\Software\e7db512d4b3e6c9c618a48908e8e70e4
[-] Key deleted: HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
[-] Key deleted: HKLM\SOFTWARE\db6911b9-5803-0365-eb22-f51abb32901d
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
[#] Key deleted on reboot: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}_is1
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2C98B47-B5F4-94AA-281D-4135416774CF}
[#] Key deleted on reboot: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2C98B47-B5F4-94AA-281D-4135416774CF}_is1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{2704AD0A-429F-47B4-B446-4FACD25D9CD8}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{2704AD0A-429F-47B4-B446-4FACD25D9CD8}
[-] Key deleted: HKLM\SOFTWARE\Classes\P2704AD0A_429F_47B4_B446_4FACD25D9CD8_.P2704AD0A_429F_47B4_B446_4FACD25D9CD8_
[-] Key deleted: HKLM\SOFTWARE\Classes\P2704AD0A_429F_47B4_B446_4FACD25D9CD8_.P2704AD0A_429F_47B4_B446_4FACD25D9CD8_.9
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E3624001-3B2C-4403-89DB-B4837BF2480E}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{E3624001-3B2C-4403-89DB-B4837BF2480E}
[-] Key deleted: HKLM\SOFTWARE\Classes\PE3624001_3B2C_4403_89DB_B4837BF2480E_.PE3624001_3B2C_4403_89DB_B4837BF2480E_
[-] Key deleted: HKLM\SOFTWARE\Classes\PE3624001_3B2C_4403_89DB_B4837BF2480E_.PE3624001_3B2C_4403_89DB_B4837BF2480E_.9
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E646CEF4-BAEF-4F63-84D9-F942C8D46684}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{E646CEF4-BAEF-4F63-84D9-F942C8D46684}
[-] Key deleted: HKLM\SOFTWARE\Classes\PE646CEF4_BAEF_4F63_84D9_F942C8D46684_.PE646CEF4_BAEF_4F63_84D9_F942C8D46684_
[-] Key deleted: HKLM\SOFTWARE\Classes\PE646CEF4_BAEF_4F63_84D9_F942C8D46684_.PE646CEF4_BAEF_4F63_84D9_F942C8D46684_.9
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{F1ABDFF5-33AC-4DCB-B6AA-0083BD0D373B}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{F1ABDFF5-33AC-4DCB-B6AA-0083BD0D373B}
[-] Key deleted: HKLM\SOFTWARE\Classes\PF1ABDFF5_33AC_4DCB_B6AA_0083BD0D373B_.PF1ABDFF5_33AC_4DCB_B6AA_0083BD0D373B_
[-] Key deleted: HKLM\SOFTWARE\Classes\PF1ABDFF5_33AC_4DCB_B6AA_0083BD0D373B_.PF1ABDFF5_33AC_4DCB_B6AA_0083BD0D373B_.9
[#] Key deleted on reboot: {A6918429-4197-42E6-A4AC-742073A9BCBB}
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataContainer.1
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataController.1
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTable.1
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableFields.1
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.DataTableHolder.1
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.LSPLogic.1
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.ReadOnlyManager.1
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController
[-] Key deleted: HKLM\SOFTWARE\Classes\LavasoftTcpServiceLib.WFPController.1
[-] Key deleted: HKLM\SOFTWARE\Classes\OCComSDK.ComSDK
[-] Key deleted: HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
[-] Key deleted: HKCU\Software\Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{0015CAC9-FC30-4CD0-BFAA-7412CC2C4DD9}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{26C7AFDB-3690-449E-B979-B0AF5CC56DD4}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3A5A5381-DAAF-4C0D-B032-2C66B3EE4A8D}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{472EF1D2-4AAE-470D-AE85-6AF8177916FD}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{8F010D54-C023-457F-AF03-497EACB6D519}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{9A754403-27B1-4ED7-96D7-588F07888EBF}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{CB31FF8F-BF80-4D2B-ADBE-12C6F5347890}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{FCAA532B-E807-4027-940C-BA16B9D50105}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[#] Key deleted on reboot: HKCU\Software\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{1F91A9A1-01BA-4C81-863D-3BA0751E1419}]
[-] Key deleted: HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\WajIEnhance
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\WEBAPP
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
[#] Key deleted on reboot: HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[#] Key deleted on reboot: HKCU\Software\WajIEnhance
[#] Key deleted on reboot: HKCU\Software\WEBAPP
[#] Key deleted on reboot: HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[#] Key deleted on reboot: HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
[-] Key deleted: HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
[-] Key deleted: HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
[-] Key deleted: HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
[-] Key deleted: HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
[-] Key deleted: HKLM\SOFTWARE\IHProtect
[-] Key deleted: HKLM\SOFTWARE\mystartsearchSoftware
[-] Key deleted: HKLM\SOFTWARE\SupDp
[-] Key deleted: HKLM\SOFTWARE\SupTab
[-] Key deleted: HKLM\SOFTWARE\Lavasoft\Web Companion
[#] Key deleted on reboot: HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
[#] Key deleted on reboot: HKLM\SOFTWARE\SUPDP
[#] Key deleted on reboot: HKLM\SOFTWARE\SUPTAB
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3H-6E62-4961-A14B-95323C512F9B}_is1
[#] Key deleted on reboot: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2C98B47-B5F4-94AA-281D-4135416774CF}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1
[-] Data restored: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] 
[-] Data restored: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Internet Explorer\Main [First Home Page] 
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] 
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [First Home Page] 
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] 
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] 
[-] Data restored: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] 
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}
[-] Key deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
[-] Data restored: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{ac93654c-9007-435e-a22b-3d76c7e67e4c} [NameServer] 
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bestpriceninja.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\mystartsearch.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.mystartsearch.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\bestpriceninja.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystartsearch.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\pstatic.bestpriceninja.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.cmptch.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.mystartsearch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\adnetworkperformance.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\bestpriceninja.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\cmptch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\eshopcomp.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\mindspark.in
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nps.pastaleads.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\onclickads.net
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pastaleads.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pstatic.bestpriceninja.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pstatic.eshopcomp.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\shopperz.utop.it
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.cmptch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\tradeadexchange.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\utop.it
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.adnetworkperformance.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.mindspark.in
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.tradeadexchange.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\adnetworkperformance.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\bestpriceninja.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\cmptch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\eshopcomp.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\mindspark.in
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nps.pastaleads.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\onclickads.net
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pastaleads.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pstatic.eshopcomp.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\shopperz.utop.it
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.cmptch.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\tradeadexchange.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\utop.it
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.adnetworkperformance.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.mindspark.in
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.tradeadexchange.com
[-] Value deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion]
[-] Value deleted: HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Web Companion]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Web Companion]
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
[-] Key deleted: HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
 
 
***** [ Web browsers ] *****
 
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [20973 Bytes] - [08/10/2016 18:30:56]
C:\AdwCleaner\AdwCleaner[S0].txt - [20888 Bytes] - [08/10/2016 18:26:14]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [21121 Bytes] ##########
 

 

Thanks,

Raman Nallamilli.



#5 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 08:16 AM

Hi Nina,

 

JRT Log:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 10 Pro x86 
Ran by admin (Administrator) on Sat 10/08/2016 at 18:40:09.25
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 2 
 
Successfully deleted: C:\Program Files\ExstraaSauvinGGs (Folder)
Successfully deleted: C:\WINDOWS\System32\Tasks\DNSNEPTUNE (Task)
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 10/08/2016 at 18:44:48.38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Thanks,

Raman Nallamilli.



#6 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 09:20 AM

MBAM Log Files:

 

Scan Log File:

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 10/8/2016
Scan Time: 7:26 PM
Logfile: 
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.10.08.03
Rootkit Database: v2016.09.26.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 10
CPU: x86
File System: NTFS
User: admin
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 309394
Time Elapsed: 22 min, 7 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
Thanks,
Raman Nallamilli.


#7 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 09:22 AM

Protection Log File:

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
 
Update, 10/8/2016 6:52 PM, SYSTEM, ADMIN-PC, Manual, Rootkit Database, 2016.2.8.1, 2016.9.26.2, 
Update, 10/8/2016 6:52 PM, SYSTEM, ADMIN-PC, Manual, Remediation Database, 2016.2.12.1, 2016.9.21.1, 
Update, 10/8/2016 6:52 PM, SYSTEM, ADMIN-PC, Manual, IP Database, 2016.2.8.1, 2016.10.6.1, 
Update, 10/8/2016 6:52 PM, SYSTEM, ADMIN-PC, Manual, Domain Database, 2016.2.16.8, 2016.10.7.3, 
Update, 10/8/2016 6:52 PM, SYSTEM, ADMIN-PC, Manual, Malware Database, 2016.2.16.6, 2016.10.8.3, 
Update, 10/8/2016 7:26 PM, SYSTEM, ADMIN-PC, Manual, Rootkit Database, 2016.2.8.1, 2016.9.26.2, 
Update, 10/8/2016 7:26 PM, SYSTEM, ADMIN-PC, Manual, Remediation Database, 2016.2.12.1, 2016.9.21.1, 
Update, 10/8/2016 7:26 PM, SYSTEM, ADMIN-PC, Manual, IP Database, 2016.2.8.1, 2016.10.8.1, 
Update, 10/8/2016 7:26 PM, SYSTEM, ADMIN-PC, Manual, Domain Database, 2016.2.16.8, 2016.10.7.3, 
Update, 10/8/2016 7:26 PM, SYSTEM, ADMIN-PC, Manual, Malware Database, 2016.2.16.6, 2016.10.8.3, 
Scan, 10/8/2016 7:48 PM, SYSTEM, ADMIN-PC, Manual, Start:10/8/2016 7:26 PM, Duration:22 min 7 sec, Threat Scan, Completed, 0 Malware Detections, 0 Non-Malware Detections, 
 
(end)
 
Thanks,
Raman Nallamilli.


#8 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:51 PM

Posted 08 October 2016 - 09:41 AM

Hello Raman - thanks for the logs.

Those scans cleared out quite a bit so let’s see what’s remaining.

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

Frst.txt
Addition.txt


Thanks

I am going out for a while now so won't be able to look at the next logs right away but will reply later.

Nina

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#9 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 11:33 AM

Hi Nina,

 

Thank You for your update. Below is the FRST Log FIle for your review.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-10-2016
Ran by admin (administrator) on ADMIN-PC (08-10-2016 21:52:14)
Running from C:\Users\admin\Desktop
Loaded Profiles: admin (Available Profiles: admin & DefaultAppPool)
Platform: Microsoft Windows 10 Pro Version 1607 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
() C:\ProgramData\DatacardService\HWDeviceService.exe
() C:\ProgramData\Idea Net Setter\OnlineUpdate\ouc.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe
(AMD) C:\Windows\System32\atieclxx.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(AO Kaspersky Lab) C:\ProgramData\Kaspersky Lab\AVP17.0.0\Temp\temporaryFolder\updates\bin\kav17\17.0.0.611_kis_b\avpui.exe.1249_2553_4126.removeOnNextReboot
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksdeui.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files\Hostless Modem\Idea Netsetter\CheckNDISPort_df.exe
() C:\Program Files\Hostless Modem\Idea Netsetter\CancelAutoPlay_df.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2485976 2015-10-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12355816 2015-09-21] (Realtek Semiconductor)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [748744 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\Run: [CheckNDISPortF0ac13] => C:\Program Files\Hostless Modem\Idea Netsetter\CheckNDISPort_df.exe [465664 2013-10-01] ()
HKLM\...\Run: [CancelAutoPlay_df] => C:\Program Files\Hostless Modem\Idea Netsetter\CancelAutoPlay_df.exe [446720 2013-10-01] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-09-19]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.376\SSScheduler.exe (McAfee, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ac93654c-9007-435e-a22b-3d76c7e67e4c}: [DhcpNameServer] 192.168.1.1
ManualProxies: 
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-147963221-2690506050-476830512-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-147963221-2690506050-476830512-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-147963221-2690506050-476830512-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [light_plugin_F6F079488B53499DB99380A7E11A93F6@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2016-06-28]
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2016-10-08]
CHR Extension: (Google Slides) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-15]
CHR Extension: (Google Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-15]
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-16]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-05]
CHR Extension: (Google Search) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-16]
CHR Extension: (Google Sheets) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-15]
CHR Extension: (Kaspersky Protection) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2016-10-08]
CHR Extension: (Google Docs Offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-07]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-15]
CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-26]
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVP17.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 BcmBtRSupport; C:\WINDOWS\system32\BtwRSupportService.exe [1680088 2013-10-28] (Broadcom Corporation.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [116952 2015-10-12] (ELAN Microelectronics Corp.)
R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [264704 2010-11-16] () [File not signed]
S2 Idea Net Setter. RunOuc; C:\Program Files\Idea Net Setter\UpdateDog\ouc.exe [218624 2015-06-09] () [File not signed]
R2 KSDE1.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.376\McCHSvc.exe [270600 2016-07-19] (McAfee, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [1887272 2016-09-15] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [271496 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [84928 2016-07-16] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 bcbtums; C:\WINDOWS\system32\drivers\bcbtums.sys [175320 2013-10-28] (Broadcom Corporation.)
S3 btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [144600 2013-10-28] (Broadcom Corporation.)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [170840 2016-06-10] (AO Kaspersky Lab)
U0 cswppg; C:\WINDOWS\System32\drivers\gtwhvab.sys [52440 2016-10-08] (Malwarebytes)
R3 ETD; C:\WINDOWS\system32\DRIVERS\ETD.sys [425032 2015-10-12] (ELAN Microelectronics Corp.)
R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [165296 2016-06-02] (AO Kaspersky Lab)
S0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [57264 2016-06-07] (AO Kaspersky Lab)
S1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [71512 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [69000 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [23168 2016-03-31] (AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [151888 2016-06-26] (AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\System32\drivers\klhk.sys [253272 2016-10-08] (AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys [165464 2016-10-08] (AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [786264 2016-10-08] (AO Kaspersky Lab)
R1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [43352 2016-10-08] (AO Kaspersky Lab)
S3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [46000 2016-05-19] (AO Kaspersky Lab)
R4 klkbdflt2; C:\WINDOWS\system32\DRIVERS\klkbdflt2.sys [39344 2016-05-23] (AO Kaspersky Lab)
S3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [37560 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [41392 2016-05-31] (AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [48056 2016-06-07] (The OpenVPN Project)
U0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [226600 2016-10-08] (AO Kaspersky Lab)
U3 klupd_klif_arkmon_442DFFB0; C:\ProgramData\Kaspersky Lab\AVP17.0.0\temp\442DFFB025DD7123E50EF1978865192D\klupd_klif_arkmon.sys [226600 2016-10-08] (AO Kaspersky Lab)
U3 klupd_klif_arkmon_62987FF7; C:\ProgramData\Kaspersky Lab\AVP17.0.0\temp\62987FF71955D0BFC9925F29484884DE\klupd_klif_arkmon.sys [216864 2016-10-08] (AO Kaspersky Lab)
U3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [223064 2016-10-08] (AO Kaspersky Lab)
U0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [97192 2016-10-08] (AO Kaspersky Lab)
U3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [143984 2016-10-08] (AO Kaspersky Lab)
U3 klupd_klif_mark_32BF35D4; C:\ProgramData\Kaspersky Lab\AVP17.0.0\temp\32BF35D46259DCD10D88F87693959A01\klupd_klif_mark.sys [153208 2016-10-08] (AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [71504 2016-06-18] (AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [108432 2016-10-08] (AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [161712 2016-06-14] (AO Kaspersky Lab)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [62976 2016-07-16] ()
R3 rt640x86; C:\WINDOWS\System32\drivers\rt640x86.sys [494080 2016-07-16] (Realtek                                            )
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37912 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [244576 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [100192 2016-07-16] (Microsoft Corporation)
U3 idsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-08 21:52 - 2016-10-08 21:54 - 00014202 _____ C:\Users\admin\Desktop\FRST.txt
2016-10-08 21:51 - 2016-10-08 21:51 - 00226600 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2016-10-08 21:51 - 2016-10-08 21:51 - 00097192 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2016-10-08 21:49 - 2016-10-08 21:52 - 00000000 ____D C:\FRST
2016-10-08 21:48 - 2016-10-08 21:48 - 01755136 _____ (Farbar) C:\Users\admin\Desktop\FRST.exe
2016-10-08 21:45 - 2016-10-08 21:45 - 00223064 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2016-10-08 20:07 - 2016-10-08 20:07 - 00143984 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2016-10-08 20:06 - 2016-10-08 20:06 - 00001365 _____ C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
2016-10-08 20:06 - 2016-10-08 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2016-10-08 20:05 - 2016-10-08 20:08 - 00000000 ____D C:\Program Files\Common Files\AV
2016-10-08 20:05 - 2016-10-08 20:05 - 00002153 _____ C:\Users\Public\Desktop\Safe Money.lnk
2016-10-08 20:05 - 2016-10-08 20:05 - 00002135 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2016-10-08 20:05 - 2016-10-08 20:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2016-10-08 20:03 - 2016-10-08 21:50 - 00786264 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2016-10-08 20:03 - 2016-10-08 21:46 - 00253272 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2016-10-08 20:03 - 2016-10-08 21:45 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-10-08 20:03 - 2016-10-08 20:05 - 00000000 ____D C:\Program Files\Kaspersky Lab
2016-10-08 20:03 - 2016-06-26 15:17 - 00151888 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2016-10-08 20:03 - 2016-06-20 17:54 - 00243536 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\SET7584.tmp
2016-10-08 20:01 - 2016-10-08 20:06 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2016-10-08 19:21 - 2016-10-08 19:21 - 00052440 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\gtwhvab.sys
2016-10-08 18:50 - 2016-10-08 19:26 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-10-08 18:49 - 2016-10-08 19:23 - 00001089 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-10-08 18:49 - 2016-10-08 19:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-10-08 18:49 - 2016-10-08 19:23 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-10-08 18:49 - 2016-10-08 18:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-10-08 18:49 - 2016-03-10 14:09 - 00053120 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-10-08 18:49 - 2016-03-10 14:08 - 00126336 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-10-08 18:49 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-10-08 18:44 - 2016-10-08 18:44 - 00000687 _____ C:\Users\admin\Desktop\JRT.txt
2016-10-08 18:22 - 2016-10-08 18:30 - 00000000 ____D C:\AdwCleaner
2016-10-08 18:05 - 2016-10-08 18:06 - 22851472 _____ (Malwarebytes ) C:\Users\admin\Desktop\mbam-setup-2.2.1.1043.exe
2016-10-08 18:04 - 2016-10-08 18:04 - 01631928 _____ (Malwarebytes) C:\Users\admin\Desktop\JRT.exe
2016-10-08 18:02 - 2016-10-08 18:02 - 03874368 _____ C:\Users\admin\Desktop\adwcleaner_6.021.exe
2016-10-04 14:32 - 2016-10-04 14:32 - 00069216 _____ C:\Users\admin\Downloads\Salary-2016 (1).xlsx
2016-10-01 08:37 - 2016-09-15 23:44 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-10-01 08:37 - 2016-09-15 23:12 - 01144600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-10-01 08:37 - 2016-09-15 23:07 - 00892008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-10-01 08:37 - 2016-09-15 23:07 - 00784576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-10-01 08:37 - 2016-09-15 23:07 - 00496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-10-01 08:37 - 2016-09-15 23:05 - 06015840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-10-01 08:37 - 2016-09-15 23:05 - 01724592 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-10-01 08:37 - 2016-09-15 23:05 - 00455040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2016-10-01 08:37 - 2016-09-15 23:05 - 00356704 _____ (Microsoft Corporation) C:\WINDOWS\system32\halmacpi.dll
2016-10-01 08:37 - 2016-09-15 23:05 - 00356704 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2016-10-01 08:37 - 2016-09-15 23:01 - 00583648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-10-01 08:37 - 2016-09-15 22:57 - 00868704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-10-01 08:37 - 2016-09-15 22:53 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-10-01 08:37 - 2016-09-15 22:52 - 02256080 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-10-01 08:37 - 2016-09-15 22:48 - 03893376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-10-01 08:37 - 2016-09-15 22:48 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-10-01 08:37 - 2016-09-15 22:48 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-10-01 08:37 - 2016-09-15 22:47 - 20965248 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-10-01 08:37 - 2016-09-15 22:44 - 01413664 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2016-10-01 08:37 - 2016-09-15 22:43 - 01276608 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-10-01 08:37 - 2016-09-15 22:43 - 01264912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-10-01 08:37 - 2016-09-15 22:43 - 00113504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2016-10-01 08:37 - 2016-09-15 22:30 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-01 08:37 - 2016-09-15 22:30 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2016-10-01 08:37 - 2016-09-15 22:30 - 00177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2016-10-01 08:37 - 2016-09-15 22:30 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
2016-10-01 08:37 - 2016-09-15 22:29 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovslegacy.dll
2016-10-01 08:37 - 2016-09-15 22:28 - 00491008 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-10-01 08:37 - 2016-09-15 22:28 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-10-01 08:37 - 2016-09-15 22:27 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2016-10-01 08:37 - 2016-09-15 22:27 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-10-01 08:37 - 2016-09-15 22:27 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2016-10-01 08:37 - 2016-09-15 22:27 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2016-10-01 08:37 - 2016-09-15 22:27 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-10-01 08:37 - 2016-09-15 22:27 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2016-10-01 08:37 - 2016-09-15 22:26 - 00823808 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2016-10-01 08:37 - 2016-09-15 22:26 - 00413184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2016-10-01 08:37 - 2016-09-15 22:25 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-10-01 08:37 - 2016-09-15 22:25 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-10-01 08:37 - 2016-09-15 22:24 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Ocr.dll
2016-10-01 08:37 - 2016-09-15 22:24 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2016-10-01 08:37 - 2016-09-15 22:24 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2016-10-01 08:37 - 2016-09-15 22:24 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2016-10-01 08:37 - 2016-09-15 22:22 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-10-01 08:37 - 2016-09-15 22:22 - 00238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-10-01 08:37 - 2016-09-15 22:19 - 00901120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-10-01 08:37 - 2016-09-15 22:19 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-10-01 08:37 - 2016-09-15 22:19 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-10-01 08:37 - 2016-09-15 22:19 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-10-01 08:37 - 2016-09-15 22:18 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-10-01 08:37 - 2016-09-15 22:17 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Energy.dll
2016-10-01 08:37 - 2016-09-15 22:16 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll
2016-10-01 08:37 - 2016-09-15 22:15 - 02749440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-10-01 08:37 - 2016-09-15 22:14 - 02153984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2016-10-01 08:37 - 2016-09-15 22:14 - 00786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-10-01 08:37 - 2016-09-15 22:13 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2016-10-01 08:37 - 2016-09-15 22:11 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2016-10-01 08:37 - 2016-09-15 22:11 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2016-10-01 08:37 - 2016-09-15 22:10 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2016-10-01 08:37 - 2016-09-15 22:09 - 02254848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-10-01 08:37 - 2016-09-15 22:08 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-10-01 08:37 - 2016-09-15 22:08 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-10-01 08:37 - 2016-09-15 22:08 - 01524224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-10-01 08:37 - 2016-09-15 22:08 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-10-01 08:37 - 2016-09-15 22:06 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2016-10-01 08:37 - 2016-09-15 22:06 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-10-01 08:36 - 2016-09-15 23:10 - 00965472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2016-10-01 08:36 - 2016-09-15 23:07 - 00320152 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-10-01 08:36 - 2016-09-15 23:05 - 00470368 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-10-01 08:36 - 2016-09-15 23:02 - 02048496 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-01 08:36 - 2016-09-15 23:02 - 00279416 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeunlock.exe
2016-10-01 08:36 - 2016-09-15 22:58 - 01015648 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-10-01 08:36 - 2016-09-15 22:53 - 01897824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-10-01 08:36 - 2016-09-15 22:53 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-01 08:36 - 2016-09-15 22:53 - 00550240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-10-01 08:36 - 2016-09-15 22:53 - 00342368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-10-01 08:36 - 2016-09-15 22:53 - 00170448 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-10-01 08:36 - 2016-09-15 22:52 - 05722320 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-10-01 08:36 - 2016-09-15 22:52 - 00433832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-10-01 08:36 - 2016-09-15 22:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2016-10-01 08:36 - 2016-09-15 22:51 - 01980776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-10-01 08:36 - 2016-09-15 22:51 - 00557920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-10-01 08:36 - 2016-09-15 22:51 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2016-10-01 08:36 - 2016-09-15 22:49 - 00361104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2016-10-01 08:36 - 2016-09-15 22:48 - 06654616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-10-01 08:36 - 2016-09-15 22:48 - 01123368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-10-01 08:36 - 2016-09-15 22:48 - 00955528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-10-01 08:36 - 2016-09-15 22:48 - 00856872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-10-01 08:36 - 2016-09-15 22:43 - 00484544 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-10-01 08:36 - 2016-09-15 22:42 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-01 08:36 - 2016-09-15 22:33 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2016-10-01 08:36 - 2016-09-15 22:30 - 00399360 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2016-10-01 08:36 - 2016-09-15 22:30 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NfcRadioMedia.dll
2016-10-01 08:36 - 2016-09-15 22:29 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2016-10-01 08:36 - 2016-09-15 22:29 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-01 08:36 - 2016-09-15 22:28 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2016-10-01 08:36 - 2016-09-15 22:28 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-10-01 08:36 - 2016-09-15 22:28 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-01 08:36 - 2016-09-15 22:28 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-10-01 08:36 - 2016-09-15 22:28 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-10-01 08:36 - 2016-09-15 22:27 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-10-01 08:36 - 2016-09-15 22:26 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2016-10-01 08:36 - 2016-09-15 22:26 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-10-01 08:36 - 2016-09-15 22:26 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2016-10-01 08:36 - 2016-09-15 22:25 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2016-10-01 08:36 - 2016-09-15 22:25 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2016-10-01 08:36 - 2016-09-15 22:25 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2016-10-01 08:36 - 2016-09-15 22:25 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2016-10-01 08:36 - 2016-09-15 22:25 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2016-10-01 08:36 - 2016-09-15 22:25 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2016-10-01 08:36 - 2016-09-15 22:24 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-10-01 08:36 - 2016-09-15 22:24 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2016-10-01 08:36 - 2016-09-15 22:23 - 01344000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2016-10-01 08:36 - 2016-09-15 22:23 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-10-01 08:36 - 2016-09-15 22:22 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-10-01 08:36 - 2016-09-15 22:22 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalLanguage6.dll
2016-10-01 08:36 - 2016-09-15 22:22 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-01 08:36 - 2016-09-15 22:22 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2016-10-01 08:36 - 2016-09-15 22:22 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprapi.dll
2016-10-01 08:36 - 2016-09-15 22:22 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2016-10-01 08:36 - 2016-09-15 22:21 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2016-10-01 08:36 - 2016-09-15 22:21 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2016-10-01 08:36 - 2016-09-15 22:21 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2016-10-01 08:36 - 2016-09-15 22:20 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2016-10-01 08:36 - 2016-09-15 22:20 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-10-01 08:36 - 2016-09-15 22:19 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-10-01 08:36 - 2016-09-15 22:18 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-10-01 08:36 - 2016-09-15 22:18 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-10-01 08:36 - 2016-09-15 22:17 - 01283584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-10-01 08:36 - 2016-09-15 22:17 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2016-10-01 08:36 - 2016-09-15 22:17 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2016-10-01 08:36 - 2016-09-15 22:17 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\RelPost.exe
2016-10-01 08:36 - 2016-09-15 22:16 - 03305984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-10-01 08:36 - 2016-09-15 22:16 - 00945664 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-10-01 08:36 - 2016-09-15 22:16 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2016-10-01 08:36 - 2016-09-15 22:16 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-10-01 08:36 - 2016-09-15 22:16 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2016-10-01 08:36 - 2016-09-15 22:15 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
2016-10-01 08:36 - 2016-09-15 22:15 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2016-10-01 08:36 - 2016-09-15 22:14 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2016-10-01 08:36 - 2016-09-15 22:14 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2016-10-01 08:36 - 2016-09-15 22:14 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-10-01 08:36 - 2016-09-15 22:14 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2016-10-01 08:36 - 2016-09-15 22:14 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvenotify.exe
2016-10-01 08:36 - 2016-09-15 22:14 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Sens.dll
2016-10-01 08:36 - 2016-09-15 22:13 - 07467520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-10-01 08:36 - 2016-09-15 22:13 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdeui.dll
2016-10-01 08:36 - 2016-09-15 22:12 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-10-01 08:36 - 2016-09-15 22:12 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2016-10-01 08:36 - 2016-09-15 22:12 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-10-01 08:36 - 2016-09-15 22:11 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-10-01 08:36 - 2016-09-15 22:10 - 03369984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-01 08:36 - 2016-09-15 22:10 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-10-01 08:36 - 2016-09-15 22:10 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-10-01 08:36 - 2016-09-15 22:10 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-10-01 08:36 - 2016-09-15 22:09 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-10-01 08:36 - 2016-09-15 22:09 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-10-01 08:36 - 2016-09-15 22:09 - 01595904 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-10-01 08:36 - 2016-09-15 22:09 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-10-01 08:36 - 2016-09-15 22:09 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-10-01 08:36 - 2016-09-15 22:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-10-01 08:36 - 2016-09-15 22:08 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-10-01 08:36 - 2016-09-15 22:06 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-10-01 08:36 - 2016-09-15 22:05 - 01438720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2016-10-01 08:36 - 2016-09-15 22:05 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2016-10-01 08:36 - 2016-09-15 22:05 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spaceman.exe
2016-10-01 08:36 - 2016-08-06 09:03 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll
2016-10-01 08:35 - 2016-09-15 23:12 - 00448864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-10-01 08:35 - 2016-09-15 23:12 - 00231776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-10-01 08:35 - 2016-09-15 23:08 - 04970224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-10-01 08:35 - 2016-09-15 23:07 - 00402352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2016-10-01 08:35 - 2016-09-15 23:05 - 01583112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-10-01 08:35 - 2016-09-15 23:05 - 01072280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-10-01 08:35 - 2016-09-15 23:05 - 00946272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-10-01 08:35 - 2016-09-15 23:04 - 00106336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-10-01 08:35 - 2016-09-15 23:03 - 00083120 _____ (Microsoft Corporation) C:\WINDOWS\system32\devenum.dll
2016-10-01 08:35 - 2016-09-15 22:56 - 00581672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2016-10-01 08:35 - 2016-09-15 22:55 - 00340320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-10-01 08:35 - 2016-09-15 22:55 - 00262960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2016-10-01 08:35 - 2016-09-15 22:52 - 00975744 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2016-10-01 08:35 - 2016-09-15 22:52 - 00860512 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-10-01 08:35 - 2016-09-15 22:51 - 00458592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-10-01 08:35 - 2016-09-15 22:51 - 00357216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2016-10-01 08:35 - 2016-09-15 22:51 - 00261984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-10-01 08:35 - 2016-09-15 22:51 - 00186720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-10-01 08:35 - 2016-09-15 22:51 - 00175968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2016-10-01 08:35 - 2016-09-15 22:50 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-10-01 08:35 - 2016-09-15 22:50 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2016-10-01 08:35 - 2016-09-15 22:49 - 00080224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-10-01 08:35 - 2016-09-15 22:47 - 01384704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-10-01 08:35 - 2016-09-15 22:47 - 00834128 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-10-01 08:35 - 2016-09-15 22:47 - 00702416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-10-01 08:35 - 2016-09-15 22:42 - 00781664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-10-01 08:35 - 2016-09-15 22:38 - 05683712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-10-01 08:35 - 2016-09-15 22:36 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ffbroker.dll
2016-10-01 08:35 - 2016-09-15 22:33 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-10-01 08:35 - 2016-09-15 22:32 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-10-01 08:35 - 2016-09-15 22:31 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2016-10-01 08:35 - 2016-09-15 22:30 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2016-10-01 08:35 - 2016-09-15 22:30 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-01 08:35 - 2016-09-15 22:30 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-10-01 08:35 - 2016-09-15 22:30 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2016-10-01 08:35 - 2016-09-15 22:29 - 00229888 _____ C:\WINDOWS\system32\wc_storage.dll
2016-10-01 08:35 - 2016-09-15 22:28 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2016-10-01 08:35 - 2016-09-15 22:28 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2016-10-01 08:35 - 2016-09-15 22:28 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-10-01 08:35 - 2016-09-15 22:28 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2016-10-01 08:35 - 2016-09-15 22:28 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-01 08:35 - 2016-09-15 22:28 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2016-10-01 08:35 - 2016-09-15 22:27 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2016-10-01 08:35 - 2016-09-15 22:27 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Input.dll
2016-10-01 08:35 - 2016-09-15 22:27 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-10-01 08:35 - 2016-09-15 22:27 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-10-01 08:35 - 2016-09-15 22:27 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-10-01 08:35 - 2016-09-15 22:27 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-10-01 08:35 - 2016-09-15 22:27 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2016-10-01 08:35 - 2016-09-15 22:26 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2016-10-01 08:35 - 2016-09-15 22:26 - 00576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-10-01 08:35 - 2016-09-15 22:26 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-10-01 08:35 - 2016-09-15 22:26 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-10-01 08:35 - 2016-09-15 22:26 - 00262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2016-10-01 08:35 - 2016-09-15 22:26 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
2016-10-01 08:35 - 2016-09-15 22:26 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-10-01 08:35 - 2016-09-15 22:25 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2016-10-01 08:35 - 2016-09-15 22:25 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-01 08:35 - 2016-09-15 22:25 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-10-01 08:35 - 2016-09-15 22:25 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2016-10-01 08:35 - 2016-09-15 22:25 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-10-01 08:35 - 2016-09-15 22:25 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-10-01 08:35 - 2016-09-15 22:25 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2016-10-01 08:35 - 2016-09-15 22:25 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\biwinrt.dll
2016-10-01 08:35 - 2016-09-15 22:24 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2016-10-01 08:35 - 2016-09-15 22:24 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2016-10-01 08:35 - 2016-09-15 22:24 - 00431104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2016-10-01 08:35 - 2016-09-15 22:24 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Picker.dll
2016-10-01 08:35 - 2016-09-15 22:23 - 00819200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2016-10-01 08:35 - 2016-09-15 22:23 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-10-01 08:35 - 2016-09-15 22:23 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2016-10-01 08:35 - 2016-09-15 22:22 - 00857600 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-10-01 08:35 - 2016-09-15 22:22 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-10-01 08:35 - 2016-09-15 22:22 - 00500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2016-10-01 08:35 - 2016-09-15 22:20 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-10-01 08:35 - 2016-09-15 22:19 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-10-01 08:35 - 2016-09-15 22:19 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-10-01 08:35 - 2016-09-15 22:19 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-10-01 08:35 - 2016-09-15 22:19 - 00608256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-10-01 08:35 - 2016-09-15 22:18 - 01321472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-10-01 08:35 - 2016-09-15 22:18 - 01112576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-10-01 08:35 - 2016-09-15 22:17 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-10-01 08:35 - 2016-09-15 22:17 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2016-10-01 08:35 - 2016-09-15 22:16 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-10-01 08:35 - 2016-09-15 22:15 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-10-01 08:35 - 2016-09-15 22:15 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-10-01 08:35 - 2016-09-15 22:14 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-01 08:35 - 2016-09-15 22:14 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-10-01 08:35 - 2016-09-15 22:14 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-10-01 08:35 - 2016-09-15 22:14 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAC3ENC.DLL
2016-10-01 08:35 - 2016-09-15 22:13 - 03196416 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-10-01 08:35 - 2016-09-15 22:13 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-10-01 08:35 - 2016-09-15 22:13 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\olepro32.dll
2016-10-01 08:35 - 2016-09-15 22:12 - 00719872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_sr.dll
2016-10-01 08:35 - 2016-09-15 22:12 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundMediaPolicy.dll
2016-10-01 08:35 - 2016-09-15 22:11 - 06043136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-10-01 08:35 - 2016-09-15 22:10 - 01488384 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-10-01 08:35 - 2016-09-15 22:10 - 01247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2016-10-01 08:35 - 2016-09-15 22:09 - 01122304 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-10-01 08:35 - 2016-09-15 22:09 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-10-01 08:35 - 2016-09-15 22:09 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-10-01 08:35 - 2016-09-15 22:09 - 00827904 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-10-01 08:35 - 2016-09-15 22:09 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-10-01 08:35 - 2016-09-15 22:09 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-10-01 08:35 - 2016-09-15 22:09 - 00240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2016-10-01 08:35 - 2016-09-15 22:08 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-10-01 08:35 - 2016-09-15 22:08 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-10-01 08:35 - 2016-09-15 22:06 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2016-10-01 08:35 - 2016-09-15 22:05 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2016-10-01 08:35 - 2016-09-15 19:35 - 00445765 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-10-01 08:34 - 2016-09-24 10:48 - 01375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-10-01 08:34 - 2016-09-24 10:37 - 01938432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-10-01 08:34 - 2016-09-15 23:12 - 00614752 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2016-10-01 08:34 - 2016-09-15 23:12 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2016-10-01 08:34 - 2016-09-15 23:12 - 00094560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\AppVStrm.sys
2016-10-01 08:34 - 2016-09-15 23:06 - 00021344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cmimcext.sys
2016-10-01 08:34 - 2016-09-15 23:00 - 00950112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-10-01 08:34 - 2016-09-15 22:53 - 00290272 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-01 08:34 - 2016-09-15 22:47 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-10-01 08:34 - 2016-09-15 22:47 - 00198496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-01 08:34 - 2016-09-15 22:47 - 00125792 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2016-10-01 08:34 - 2016-09-15 22:46 - 00093984 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2016-10-01 08:34 - 2016-09-15 22:33 - 00012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2016-10-01 08:34 - 2016-09-15 22:32 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2016-10-01 08:34 - 2016-09-15 22:31 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2016-10-01 08:34 - 2016-09-15 22:31 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2016-10-01 08:34 - 2016-09-15 22:29 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinRtTracing.dll
2016-10-01 08:34 - 2016-09-15 22:28 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2016-10-01 08:34 - 2016-09-15 22:27 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2016-10-01 08:34 - 2016-09-15 22:27 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2016-10-01 08:34 - 2016-09-15 22:27 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2016-10-01 08:34 - 2016-09-15 22:26 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkCollectionAgent.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrGidsHandler.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-10-01 08:34 - 2016-09-15 22:25 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-10-01 08:34 - 2016-09-15 22:24 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll
2016-10-01 08:34 - 2016-09-15 22:24 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2016-10-01 08:34 - 2016-09-15 22:23 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2016-10-01 08:34 - 2016-09-15 22:23 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2016-10-01 08:34 - 2016-09-15 22:22 - 01110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-10-01 08:34 - 2016-09-15 22:22 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2016-10-01 08:34 - 2016-09-15 22:22 - 00525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2016-10-01 08:34 - 2016-09-15 22:22 - 00441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2016-10-01 08:34 - 2016-09-15 22:21 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2016-10-01 08:34 - 2016-09-15 22:20 - 07625728 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-10-01 08:34 - 2016-09-15 22:20 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwrshplugin.dll
2016-10-01 08:34 - 2016-09-15 22:19 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-10-01 08:34 - 2016-09-15 22:19 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2016-10-01 08:34 - 2016-09-15 22:17 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\baaupdate.exe
2016-10-01 08:34 - 2016-09-15 22:15 - 12174848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-10-01 08:34 - 2016-09-15 22:15 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2016-10-01 08:34 - 2016-09-15 22:15 - 00671744 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
2016-10-01 08:34 - 2016-09-15 22:14 - 12345856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-10-01 08:34 - 2016-09-15 22:14 - 00158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveprompt.exe
2016-10-01 08:34 - 2016-09-15 22:13 - 03520512 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2016-10-01 08:34 - 2016-09-15 22:13 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
2016-10-01 08:34 - 2016-09-15 22:13 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2016-10-01 08:34 - 2016-09-15 22:12 - 03776000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-10-01 08:34 - 2016-09-15 22:11 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-10-01 08:34 - 2016-09-15 22:10 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2016-10-01 08:34 - 2016-09-15 22:10 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll
2016-10-01 08:34 - 2016-09-15 22:10 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-10-01 08:34 - 2016-09-15 22:09 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-10-01 08:34 - 2016-09-15 22:09 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2016-10-01 08:34 - 2016-09-15 22:09 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2016-10-01 08:34 - 2016-09-15 22:09 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-01 08:34 - 2016-09-15 22:09 - 00711168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-10-01 08:34 - 2016-09-15 22:09 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-01 08:34 - 2016-09-15 22:08 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2016-10-01 08:34 - 2016-09-15 22:08 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-01 08:34 - 2016-09-15 22:08 - 00654336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2016-10-01 08:33 - 2016-09-15 22:52 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-01 08:33 - 2016-09-15 22:36 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-10-01 08:33 - 2016-09-15 22:31 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2016-10-01 08:33 - 2016-09-15 22:30 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.Client.dll
2016-10-01 08:33 - 2016-09-15 22:29 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-01 08:33 - 2016-09-15 22:28 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2016-10-01 08:33 - 2016-09-15 22:28 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlancfg.dll
2016-10-01 08:33 - 2016-09-15 22:28 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Family.SyncEngine.dll
2016-10-01 08:33 - 2016-09-15 22:27 - 03716096 _____ (Microsoft Corporation) C:\WINDOWS\system32\bootux.dll
2016-10-01 08:33 - 2016-09-15 22:26 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2016-10-01 08:33 - 2016-09-15 22:26 - 00265728 _____ C:\WINDOWS\system32\Windows.Perception.Stub.dll
2016-10-01 08:33 - 2016-09-15 22:25 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-10-01 08:33 - 2016-09-15 22:25 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-01 08:33 - 2016-09-15 22:22 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2016-10-01 08:33 - 2016-09-15 22:16 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2016-10-01 08:33 - 2016-09-15 22:15 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2016-10-01 08:33 - 2016-09-15 22:13 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2016-10-01 08:33 - 2016-09-15 22:10 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-09-27 18:46 - 2016-09-27 18:46 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2016-09-26 11:10 - 2016-09-26 11:13 - 08966026 _____ C:\Users\admin\Downloads\Vriliso brochure.pdf
2016-09-24 15:37 - 2016-09-24 15:37 - 00001509 _____ C:\Users\admin\Desktop\People.lnk
2016-09-23 15:35 - 2016-09-23 15:37 - 00279676 _____ C:\WINDOWS\Minidump\092316-28484-01.dmp
2016-09-23 15:35 - 2016-09-23 15:35 - 00000000 ____D C:\WINDOWS\Minidump
2016-09-23 07:21 - 2016-09-22 18:57 - 00000000 ___DC C:\WINDOWS\Panther
2016-09-23 07:13 - 2016-09-23 07:13 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-09-23 07:13 - 2016-09-23 07:13 - 06534656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 03595264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01997824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01968480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-09-23 07:13 - 2016-09-23 07:13 - 01966288 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01853232 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01842688 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01362504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-09-23 07:13 - 2016-09-23 07:13 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2016-09-23 07:13 - 2016-09-23 07:13 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00292184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2016-09-23 07:13 - 2016-09-23 07:13 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-09-23 07:13 - 2016-09-23 07:13 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00092000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-09-23 07:13 - 2016-09-23 07:13 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe
2016-09-23 07:13 - 2016-09-23 07:13 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-09-23 07:13 - 2016-09-23 07:13 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2016-09-23 07:12 - 2016-09-23 07:13 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 05376000 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 04557824 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-09-23 07:12 - 2016-09-23 07:12 - 02423296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 02360832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 02318336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 02107392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01957216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 01885696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01774080 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01344992 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 01056768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00959104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00920576 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00798504 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00761344 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00755200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00601200 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00589144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00582144 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00570720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00564488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00461312 _____ (Microsoft) C:\WINDOWS\system32\DbgModel.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00432328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00399712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00321792 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00315736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00260448 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL
2016-09-23 07:12 - 2016-09-23 07:12 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-09-23 07:12 - 2016-09-23 07:12 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00154976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00145248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00141824 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00133296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00127168 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\EhStorTcgDrv.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00094528 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-09-23 07:12 - 2016-09-23 07:12 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConfigureExpandedStorage.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AddressParser.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00054624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactActivation.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00043944 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00036704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys
2016-09-23 07:12 - 2016-09-23 07:12 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00023776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL
2016-09-23 07:12 - 2016-09-23 07:12 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL
2016-09-23 07:12 - 2016-09-23 07:12 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2016-09-23 07:12 - 2016-09-23 07:12 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccessRes.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx
2016-09-23 07:12 - 2016-09-23 07:12 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneutilRes.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneServiceRes.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-09-23 07:04 - 2016-09-23 07:04 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-09-23 07:01 - 2016-09-23 07:01 - 00000000 ____D C:\WINDOWS\system32\msmq
2016-09-23 07:01 - 2016-09-23 07:01 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2016-09-23 07:01 - 2016-09-23 07:01 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-09-23 07:01 - 2016-09-23 07:01 - 00000000 ____D C:\inetpub
2016-09-23 07:01 - 2016-09-22 18:21 - 00000000 ____D C:\Program Files\MSBuild
2016-09-23 07:00 - 2016-05-26 00:33 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-09-23 07:00 - 2016-05-26 00:33 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-09-23 07:00 - 2016-05-26 00:33 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-09-23 06:59 - 2016-09-23 06:59 - 00173408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2016-09-22 19:03 - 2016-09-22 19:03 - 00001047 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2016-09-22 19:03 - 2016-09-22 19:03 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-09-22 18:58 - 2016-09-23 15:43 - 00000000 ____D C:\Users\admin\AppData\Local\ConnectedDevicesPlatform
2016-09-22 18:57 - 2016-09-22 18:57 - 00000020 ___SH C:\Users\admin\ntuser.ini
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 _SHDL C:\Users\Default\My Documents
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-09-22 18:56 - 2016-09-22 18:56 - 00000000 ____D C:\ProgramData\USOShared
2016-09-22 18:53 - 2016-09-22 18:55 - 00011433 _____ C:\WINDOWS\diagwrn.xml
2016-09-22 18:53 - 2016-09-22 18:55 - 00011433 _____ C:\WINDOWS\diagerr.xml
2016-09-22 18:32 - 2016-10-08 18:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-09-22 18:20 - 2016-09-22 18:20 - 00001487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-09-22 18:20 - 2016-09-22 18:20 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-09-22 18:20 - 2016-09-22 18:20 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI
2016-09-22 18:20 - 2016-09-22 18:20 - 00000000 ____D C:\Users\Default\AppData\Local\ATI
2016-09-22 18:20 - 2016-09-22 18:20 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-09-22 18:20 - 2016-09-22 18:20 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI
2016-09-22 18:20 - 2016-09-22 18:20 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI
2016-09-22 18:12 - 2016-09-22 18:12 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2016-09-22 18:07 - 2016-09-22 18:21 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-09-22 18:03 - 2016-10-08 19:54 - 00000000 ____D C:\Users\admin
2016-09-22 18:03 - 2016-09-27 18:46 - 00000000 ____D C:\Users\DefaultAppPool
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\DefaultAppPool\My Documents
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Videos
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Pictures
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Music
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\admin\My Documents
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\admin\Documents\My Videos
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\admin\Documents\My Pictures
2016-09-22 18:03 - 2016-09-22 18:03 - 00000000 _SHDL C:\Users\admin\Documents\My Music
2016-09-22 18:01 - 2016-10-04 14:27 - 01016422 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-09-22 17:57 - 2016-09-22 17:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2016-09-22 17:57 - 2016-09-22 17:57 - 00000000 ____D C:\ProgramData\AMD
2016-09-22 17:56 - 2016-09-22 18:12 - 00000000 ____D C:\Program Files\Realtek
2016-09-22 17:56 - 2016-09-22 17:57 - 00000000 ____D C:\Program Files\ATI Technologies
2016-09-22 17:56 - 2016-09-22 17:56 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_ETD_01009.Wdf
2016-09-22 17:56 - 2016-09-22 17:56 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-09-22 17:56 - 2016-09-22 17:56 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2016-09-22 17:56 - 2016-09-22 17:56 - 00000000 ____D C:\WINDOWS\system32\RTCOM
2016-09-22 17:56 - 2016-09-22 17:56 - 00000000 ____D C:\ProgramData\Package Cache
2016-09-22 17:55 - 2016-09-22 18:21 - 00000000 ____D C:\Program Files\Elantech
2016-09-22 17:55 - 2016-09-22 17:55 - 00000000 ____D C:\Program Files\AMD
2016-09-22 17:55 - 2016-09-22 17:55 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2016-09-22 17:53 - 2016-10-08 17:51 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-09-22 17:53 - 2016-09-23 15:35 - 00340576 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-09-22 17:53 - 2016-09-22 17:53 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-09-22 16:05 - 2016-09-22 12:39 - 177903608 _____ (Kaspersky Lab) C:\Users\admin\Downloads\kis17.0.0.611en-in_full.exe
2016-09-19 20:46 - 2016-09-22 18:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-09-19 20:46 - 2016-09-19 20:46 - 00002078 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-09-14 17:47 - 2016-09-14 17:50 - 17872984 _____ C:\Users\admin\Downloads\New Compressed (zipped) Folder.zip
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-08 21:52 - 2016-07-16 13:58 - 00000000 ____D C:\WINDOWS\INF
2016-10-08 21:49 - 2016-06-20 23:41 - 00043352 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2016-10-08 21:49 - 2016-06-02 22:39 - 00108432 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2016-10-08 20:05 - 2016-07-16 07:52 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2016-10-08 20:03 - 2016-07-16 13:59 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-10-08 20:03 - 2015-10-30 10:43 - 00000000 ____D C:\Users\Default.migrated
2016-10-08 19:21 - 2015-08-07 02:45 - 00000000 ____D C:\Program Files\Better  Tasks
2016-10-08 19:21 - 2015-08-07 02:43 - 00000000 ____D C:\Program Files\ExxstraSaviNgss
2016-10-08 19:09 - 2016-07-16 13:59 - 00000000 ___HD C:\Program Files\WindowsApps
2016-10-08 19:09 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-10-08 18:47 - 2015-08-07 01:00 - 00000000 ____D C:\Program Files\CuttThePrIce
2016-10-08 18:31 - 2016-07-16 07:52 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-10-08 18:29 - 2015-08-07 01:18 - 00000000 ____D C:\Users\admin\AppData\Roaming\Lavasoft
2016-10-08 18:29 - 2015-08-07 01:17 - 00000000 ____D C:\ProgramData\Lavasoft
2016-10-08 18:29 - 2015-08-07 01:17 - 00000000 ____D C:\Program Files\Lavasoft
2016-10-06 18:29 - 2015-08-07 09:37 - 00000000 ____D C:\Users\admin\AppData\Local\Packages
2016-10-05 14:22 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\rescache
2016-10-03 08:27 - 2015-08-07 09:38 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-10-02 19:14 - 2016-07-16 15:48 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\setup
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\Provisioning
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-10-02 19:14 - 2016-07-16 13:59 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-10-02 19:14 - 2016-07-16 07:52 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-10-02 19:14 - 2016-07-16 07:52 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-10-02 16:26 - 2016-07-16 13:49 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-09-30 20:08 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-09-23 09:16 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\appcompat
2016-09-23 07:21 - 2016-07-16 14:00 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-09-23 07:14 - 2016-07-16 13:59 - 00000000 ___SD C:\WINDOWS\system32\dsc
2016-09-23 07:14 - 2016-07-16 13:59 - 00000000 ___RD C:\Program Files\Windows Defender
2016-09-23 07:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\es-MX
2016-09-23 07:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-09-23 07:01 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-09-23 07:01 - 2016-07-16 13:56 - 01003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2016-09-23 07:01 - 2016-07-16 13:56 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2016-09-23 07:01 - 2016-07-16 13:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2016-09-23 07:01 - 2016-07-16 13:56 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2016-09-23 07:01 - 2016-07-16 13:56 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2016-09-23 07:01 - 2016-07-16 13:56 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2016-09-23 07:01 - 2016-07-16 13:56 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2016-09-23 07:01 - 2016-07-16 13:56 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2016-09-23 07:01 - 2016-07-16 13:56 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2016-09-23 07:01 - 2016-07-16 13:56 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2016-09-23 07:00 - 2016-07-16 13:56 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2016-09-23 06:47 - 2016-01-04 04:15 - 00000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2016-09-22 19:37 - 2015-08-07 09:49 - 00002401 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-09-22 19:37 - 2015-08-07 09:49 - 00000000 ___RD C:\Users\admin\OneDrive
2016-09-22 18:56 - 2016-07-16 13:59 - 00000000 ____D C:\ProgramData\USOPrivate
2016-09-22 18:52 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-09-22 18:52 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\Registration
2016-09-22 18:52 - 2015-10-30 11:18 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2016-09-22 18:34 - 2015-08-07 09:45 - 00000000 ____D C:\WINDOWS\system32\NETGEAR
2016-09-22 18:32 - 2015-08-07 09:30 - 00021412 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-09-22 18:30 - 2016-07-16 13:59 - 00000000 __RHD C:\Users\Public\Libraries
2016-09-22 18:30 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\Media
2016-09-22 18:22 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2016-09-22 18:21 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-09-22 18:21 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2016-09-22 18:21 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2016-09-22 18:21 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\et-EE
2016-09-22 18:21 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-09-22 18:21 - 2015-10-30 12:28 - 00000000 ____D C:\WINDOWS\ShellNew
2016-09-22 18:21 - 2015-06-15 23:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Idea Netsetter
2016-09-22 18:21 - 2015-06-10 12:17 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broadcom Wireless
2016-09-22 18:21 - 2015-06-10 12:16 - 00000000 ____D C:\WINDOWS\system32\vs08
2016-09-22 18:21 - 2015-06-09 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-09-22 18:21 - 2015-06-09 14:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Idea Net Setter
2016-09-22 18:20 - 2016-07-16 13:59 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-09-22 18:15 - 2016-07-16 15:45 - 00000000 ____D C:\WINDOWS\system32\winrm
2016-09-22 18:15 - 2016-07-16 15:45 - 00000000 ____D C:\WINDOWS\system32\WCN
2016-09-22 18:15 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-09-22 18:15 - 2015-07-24 16:57 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2016-09-22 18:14 - 2016-07-16 15:45 - 00000000 ____D C:\WINDOWS\system32\slmgr
2016-09-22 18:14 - 2016-07-16 15:45 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2016-09-22 18:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\spool
2016-09-22 18:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-09-22 18:14 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\system32\IME
2016-09-22 18:14 - 2015-06-17 10:59 - 00000000 ____D C:\WINDOWS\system32\SPReview
2016-09-22 18:14 - 2015-06-15 23:52 - 00000000 ____D C:\WINDOWS\system32\SupportAppPBHostless Modem
2016-09-22 18:13 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\schemas
2016-09-22 18:13 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-09-22 18:13 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\IME
2016-09-22 18:13 - 2016-07-16 13:59 - 00000000 ____D C:\WINDOWS\Help
2016-09-22 18:13 - 2015-06-12 15:17 - 00000000 ____D C:\WINDOWS\system32\EventProviders
2016-09-22 18:13 - 2009-07-14 13:18 - 00000000 ___RD C:\Users\Public\Recorded TV
2016-09-22 18:12 - 2016-07-16 13:59 - 00000000 __SHD C:\Program Files\Windows Sidebar
2016-09-22 18:12 - 2016-07-16 13:59 - 00000000 ____D C:\Program Files\Common Files\System
2016-09-22 18:12 - 2016-07-16 13:59 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-09-22 18:12 - 2015-08-07 01:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2016-09-22 18:12 - 2009-07-14 10:22 - 00000000 ____D C:\Program Files\Microsoft Games
2016-09-22 17:58 - 2016-07-16 13:59 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-09-22 17:58 - 2016-07-16 13:59 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-09-22 17:55 - 2015-08-07 08:58 - 00000000 ____D C:\AMD
2016-09-22 14:15 - 2015-08-15 20:21 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-22 11:15 - 2015-08-15 20:21 - 00000908 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-19 20:54 - 2015-09-15 10:40 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-09-18 09:10 - 2015-06-09 14:40 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-09-18 08:52 - 2015-06-09 14:40 - 141747376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-09-18 08:26 - 2015-08-15 20:22 - 00002208 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
 
==================== Files in the root of some directories =======
 
2016-01-30 18:44 - 2016-01-30 18:44 - 0004096 ____H () C:\Users\admin\AppData\Local\keyfile3.drm
2016-09-22 17:56 - 2016-09-22 17:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-10-06 19:11
 
==================== End of FRST.txt ============================

 

 

Thanks,

Raman Nallamilli.



#10 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 11:35 AM

Addition Log File:

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-10-2016
Ran by admin (08-10-2016 21:56:28)
Running from C:\Users\admin\Desktop
Microsoft Windows 10 Pro Version 1607 (X86) (2016-09-22 13:27:08)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
admin (S-1-5-21-147963221-2690506050-476830512-1000 - Administrator - Enabled) => C:\Users\admin
Administrator (S-1-5-21-147963221-2690506050-476830512-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-147963221-2690506050-476830512-503 - Limited - Disabled)
Guest (S-1-5-21-147963221-2690506050-476830512-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-147963221-2690506050-476830512-1002 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kaspersky Internet Security (Enabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
AMD Catalyst Control Center (HKLM\...\WUCCCApp) (Version: 1.00.0000 - AMD)
Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.60.48.55 - Broadcom Corporation)
Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
ETDWare X86 15.7.0.1_WHQL (HKLM\...\Elantech) (Version: 15.7.0.1 - ELAN Microelectronic Corp.)
Google Chrome (HKLM\...\Google Chrome) (Version: 53.0.2785.116 - Google Inc.)
Google Update Helper (Version: 1.3.31.5 - Google Inc.) Hidden
Idea Net Setter (HKLM\...\Idea Net Setter) (Version: 21.005.11.00.356 - Huawei Technologies Co.,Ltd)
Idea Netsetter (HKLM\...\{AEFF9E60-3E93-41EE-9895-311F7D1C5FFD}) (Version: 1.0.0.2 - ZTE Corporation)
Kaspersky Internet Security (HKLM\...\InstallWIX_{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Internet Security (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM\...\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Secure Connection (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.376.2 - McAfee, Inc.)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft® Windows® Operating System 7.0 (HKLM\...\Microsoft® Windows® Operating System 7.0) (Version: 7.0 - Microsoft Corporation)
PathModule (HKLM\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{3ab4b6}) (Version:  - PathModule) <==== ATTENTION
Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.40.126.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7543 - Realtek Semiconductor Corp.)
Web Companion (HKLM\...\{905025cf-65ce-4caa-b40b-d1f51c1b4968}) (Version: 2.3.1411.2698 - Lavasoft)
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.8800 - Broadcom Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.27.5\psuser.dll => No File
CustomCLSID: HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.26.9\psuser.dll => No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02CA5B98-8FB1-4BFD-93DA-006CBBB4E724} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {086E2293-F137-4623-84D1-3A476BEC0F75} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-15] (Google Inc.)
Task: {0AC933E7-0B9A-492F-92B1-839EDE5A6290} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {0CB5DFD5-C6C4-4174-B335-5076CACDC4B2} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {283147C7-FE35-4B69-B060-1B0F13A8573B} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {2CA8C456-C5D5-439B-B176-2EC2AE8F03BB} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3090014A-E635-4ADA-847C-53F48F55487E} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {390BAD78-261E-4515-AE07-1793D49AA6F9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {3A1AECC4-C1FE-4521-BCFA-819ACEFFFB7E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {3B284F0D-EEB5-4714-9A9D-C4081F7BDAD3} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {3FB78968-1099-48A8-A7E4-CDCFD8B7B2DC} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {44980B3B-9FB9-45FE-BF3C-0A84BE9C11EB} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {496ECCB1-559F-4894-93F8-0E01479E6FE7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {50C7E7E0-6A44-42B3-9E8D-3FCFC55BBE8A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {546C9F83-8FF1-4F0B-BD86-4B8378EF334A} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {6716136F-C912-4D9E-B669-69C15FAD78AA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {7554DA3D-558C-4BF3-BCD2-78ABA7A13B14} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {79AC5678-C262-433D-8232-588FC1130B1F} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7A1E3FEF-F0D2-4029-BEA7-1FB6274301D0} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {8A4A91DF-4BA6-4310-B4F3-F0B15D95078C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8EC06971-96F5-4256-9ACF-3CDC86C0F986} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [2016-07-11] (AO Kaspersky Lab)
Task: {8FE5EB09-94EB-4BE9-86B9-3499B2F3EF1B} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {99BCA9F2-870A-4E39-8DDF-E0B6B006C7DE} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A16EA3DB-2E0E-4ED9-BC08-F0A21112D43A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A8DCDE9B-4351-41B7-A5C5-57013ADAD09F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {AE273A79-6256-4013-B7F6-D1175EA688C5} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {AEF2FAE6-637F-4015-A5FD-8017D90749E3} - System32\Tasks\{C3E97EB2-2C5E-487B-93DC-D89FC63543C1} => C:\WLAN_Atheros_Win7_9.2.0.470\Inst.exe [2010-09-02] (Samsung Electronics Co., Ltd.)
Task: {AF917C1A-F606-4DC7-9A37-4E99D0464D45} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B0933D71-D287-483C-B9A9-CE72FACF09BB} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {B240FE2D-176D-40FD-9365-598973EA0621} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {CB62CC12-9B3F-444D-9EAF-F5C609A72600} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {CC762BF3-1B0F-451D-BB80-4C4D29EE4574} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {D2B6BAC8-6ECC-4B97-BE74-DE16864022B0} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DBB4C87D-6909-4321-A734-8184ABDE43C0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DFEB099A-8B2A-4AD2-95FA-F2B784BFA49B} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-08-14] (Microsoft Corporation)
Task: {E466C52A-74DC-405D-B550-5F760C4C9D9D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {EFC6AF24-C785-4C2C-B40D-159AD5B60E00} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-15] (Google Inc.)
Task: {F24F1816-8E2A-45FA-873F-29C6FF2FC0E2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {F8B84DE2-DF0A-491D-A6FF-3A0D40CA07D9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {FD84BFBD-5F87-4AFC-905D-1A0D637B6900} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-quic
ShortcutWithArgument: C:\Users\Public\Desktop\Idea Netsetter.lnk -> C:\Program Files\Hostless Modem\Idea Netsetter\LaunchWebUI.exe () -> hxxp://192.168.0.1/index.asp
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-08-21 22:08 - 2015-08-21 22:08 - 00114688 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2010-11-16 19:07 - 2010-11-16 19:07 - 00264704 _____ () C:\ProgramData\DatacardService\HWDeviceService.exe
2015-06-09 14:29 - 2015-06-09 14:28 - 00218624 _____ () C:\ProgramData\Idea Net Setter\OnlineUpdate\ouc.exe
2015-06-09 14:29 - 2015-06-09 14:28 - 00011362 _____ () C:\ProgramData\Idea Net Setter\OnlineUpdate\mingwm10.dll
2015-06-09 14:29 - 2015-06-09 14:28 - 00043008 _____ () C:\ProgramData\Idea Net Setter\OnlineUpdate\libgcc_s_dw2-1.dll
2015-06-09 14:29 - 2015-06-09 14:28 - 02415104 _____ () C:\ProgramData\Idea Net Setter\OnlineUpdate\QtCore4.dll
2015-06-09 14:29 - 2015-06-09 14:28 - 01148416 _____ () C:\ProgramData\Idea Net Setter\OnlineUpdate\QtNetwork4.dll
2016-06-28 00:19 - 2016-06-28 00:19 - 00865232 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\kpcengine.2.3.dll
2016-07-16 13:55 - 2016-07-16 13:55 - 00190976 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-10-01 08:36 - 2016-09-15 23:02 - 02048496 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-10-01 08:36 - 2016-09-15 23:02 - 02048496 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-06-15 23:52 - 2013-10-01 05:40 - 00465664 _____ () C:\Program Files\Hostless Modem\Idea Netsetter\CheckNDISPort_df.exe
2015-06-15 23:52 - 2013-10-01 05:40 - 00446720 _____ () C:\Program Files\Hostless Modem\Idea Netsetter\CancelAutoPlay_df.exe
2016-09-22 19:14 - 2016-09-22 19:16 - 01383616 _____ () C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\ClientTelemetry.dll
2016-09-22 19:20 - 2016-09-22 19:20 - 00118976 _____ () C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6517.0809_1\FileSyncViews.dll
2015-08-21 22:08 - 2015-08-21 22:08 - 00095744 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2016-07-16 13:55 - 2016-07-16 13:55 - 00185368 _____ () c:\windows\system32\WerEtw.dll
2016-10-01 08:36 - 2016-09-15 23:02 - 02048496 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-07-16 13:55 - 2016-07-16 13:55 - 00109056 _____ () C:\WINDOWS\SYSTEM32\CHARTV.dll
2016-07-16 13:55 - 2016-07-16 13:55 - 00108032 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00321536 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-10-01 08:34 - 2016-09-15 22:14 - 06726656 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-10-01 08:34 - 2016-09-15 22:06 - 01149440 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-09-23 07:12 - 2016-09-23 07:12 - 00526848 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-10-01 08:34 - 2016-09-15 22:07 - 00779776 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-10-01 08:34 - 2016-09-15 22:06 - 01725440 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-10-01 08:34 - 2016-09-15 22:08 - 03158016 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-18 08:26 - 2016-09-14 06:08 - 01806152 _____ () C:\Program Files\Google\Chrome\Application\53.0.2785.116\libglesv2.dll
2016-09-18 08:26 - 2016-09-14 06:08 - 00094024 _____ () C:\Program Files\Google\Chrome\Application\53.0.2785.116\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-147963221-2690506050-476830512-1000\...\localhost -> localhost
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 07:34 - 2016-09-19 20:47 - 00000867 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
0.0.0.1 mssplus.mcafee.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-147963221-2690506050-476830512-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-32bit] => (Allow) LPort=808
FirewallRules: [{B852B171-9BF3-4CE6-86E6-4B18A6D0AD29}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{3A2CA75C-B6A0-47FC-B3AA-083186EDE64F}] => (Allow) C:\Users\admin\AppData\Local\Temp\server.exe
FirewallRules: [{232FAC7A-B32D-40D5-A6FE-9A7BBB1EE173}] => (Allow) C:\Users\admin\AppData\Local\Temp\server.exe
FirewallRules: [{9441CF9E-9E80-402C-83F9-CA376AD349C1}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/08/2016 09:51:04 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.14393.206 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1b5c
 
Start Time: 01d2217e513a669c
 
Termination Time: 0
 
Application Path: C:\Windows\explorer.exe
 
Report Id: e7f75952-8d71-11e6-93f6-e8039a3179ea
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (10/08/2016 07:55:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "c:\program files\ati technologies\ati.ace\core-static\SLSTaskbar64.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/08/2016 07:25:05 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "c:\program files\ati technologies\ati.ace\core-static\SLSTaskbar64.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/08/2016 07:22:57 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "c:\program files\ati technologies\ati.ace\core-static\SLSTaskbar64.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/08/2016 06:51:05 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "c:\program files\ati technologies\ati.ace\core-static\SLSTaskbar64.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/08/2016 06:09:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a557c0
Faulting module name: wpaxholder.dll, version: 10.0.14393.206, time stamp: 0x57dad26c
Exception code: 0xc0000409
Fault offset: 0x0002078d
Faulting process id: 0x1d00
Faulting application start time: 0x01d22158dcf3455e
Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
Faulting module path: C:\WINDOWS\SYSTEM32\wpaxholder.dll
Report Id: ad0a3981-a0ec-4aa3-9f57-35afd89b1bac
Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
Faulting package-relative application ID: MicrosoftEdge
 
Error: (10/08/2016 05:53:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ADMIN-PC)
Description: Activation of app Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/08/2016 05:53:01 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ADMIN-PC)
Description: Activation of app Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/08/2016 08:40:38 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ADMIN-PC)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (10/08/2016 08:40:38 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ADMIN-PC)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
 
System errors:
=============
Error: (10/08/2016 09:52:32 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (10/08/2016 09:52:12 PM) (Source: KLIF) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (10/08/2016 09:50:22 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer RNALLAMILLI
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{AC93654C-9007-435E-A22B-3D76C7.
The master browser is stopping or an election is being forced.
 
Error: (10/08/2016 09:39:19 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (10/08/2016 08:04:39 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer RNALLAMILLI
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{AC93654C-9007-435E-A22B-3D76C7.
The master browser is stopping or an election is being forced.
 
Error: (10/08/2016 07:55:12 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (10/08/2016 06:40:47 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer RNALLAMILLI
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{AC93654C-9007-435E-A22B-3D76C7.
The master browser is stopping or an election is being forced.
 
Error: (10/08/2016 06:32:55 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (10/08/2016 06:32:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Idea Net Setter. RunOuc service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (10/08/2016 06:32:32 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Idea Net Setter. RunOuc service to connect.
 
 
CodeIntegrity:
===================================
  Date: 2016-10-05 14:00:53.735
  Description: N/A
 
  Date: 2016-10-04 09:12:29.368
  Description: N/A
 
  Date: 2016-10-04 09:07:02.851
  Description: N/A
 
  Date: 2016-10-04 09:06:59.395
  Description: N/A
 
  Date: 2016-10-04 09:01:57.891
  Description: N/A
 
  Date: 2016-10-04 09:01:43.324
  Description: N/A
 
  Date: 2016-10-04 09:01:37.425
  Description: N/A
 
  Date: 2016-10-04 08:45:43.382
  Description: N/A
 
  Date: 2016-09-24 15:35:58.998
  Description: N/A
 
 
==================== Memory info =========================== 
 
Processor: AMD E-450 APU with Radeon™ HD Graphics
Percentage of memory in use: 71%
Total physical RAM: 1788.12 MB
Available physical RAM: 501.39 MB
Total Virtual: 3580.12 MB
Available Virtual: 1680.95 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:48.73 GB) (Free:16.02 GB) NTFS
Drive d: (New Volume) (Fixed) (Total:83.09 GB) (Free:49.06 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:83.09 GB) (Free:69.74 GB) NTFS
Drive f: (New Volume) (Fixed) (Total:83.09 GB) (Free:51.76 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: A33B6C03)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=48.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=83.1 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=166.2 GB) - (Type=OF Extended)
 
==================== End of Addition.txt ============================

 

 

Thanks,

Raman Nallamilli.



#11 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:51 PM

Posted 08 October 2016 - 02:56 PM

I don’t think there has been much damage done. There are some things to tidy up and we’ll do an online scan.

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-147963221-2690506050-476830512-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-147963221-2690506050-476830512-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CustomCLSID: HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.27.5\psuser.dll => No File
CustomCLSID: HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.26.9\psuser.dll => No File
Task: {02CA5B98-8FB1-4BFD-93DA-006CBBB4E724} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {390BAD78-261E-4515-AE07-1793D49AA6F9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {3B284F0D-EEB5-4714-9A9D-C4081F7BDAD3} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {3FB78968-1099-48A8-A7E4-CDCFD8B7B2DC} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {496ECCB1-559F-4894-93F8-0E01479E6FE7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {6716136F-C912-4D9E-B669-69C15FAD78AA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {7A1E3FEF-F0D2-4029-BEA7-1FB6274301D0} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {E466C52A-74DC-405D-B550-5F760C4C9D9D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {F24F1816-8E2A-45FA-873F-29C6FF2FC0E2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

===================================================

Run ESET Online Scan

Note: This may take a long time so please be patient.

IMPORTANT Please make sure you uncheck the box next to Remove found threats. Eset will detect anything that looks even slightly suspicious, which could include legitimate program files. If you do not uncheck the box, Eset will automatically remove all suspicious files which could leave some of your software inoperable.

Note: You can use Internet Explorer, FireFox or Chrome for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan

  • click the Run Eset online Scanner button
  • for alternate browsers only: (Microsoft Internet Explorer users can skip these steps)


    o    click on esetinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    o    double click on the Eset installer icon on your desktop
     

  • check Yes, I accept the Terms of Use
  • click the Start button
  • accept any security warnings from your browser
  • check Enable detection of potentially unwanted applications
  • click Advanced settings and select the following:


    o    scan archives
    o    scan for potentially unsafe applications
    o    enable Anti-Stealth technology

    Note: Do not check Remove found threats
     

  • ESET will then download updates, install itself, and begin scanning your computer, (lease be patient as this can take some time)
  • when the scan completes, push List of found threats
  • when the scan is done, click List threats (only available if ESET Online Scanner found something)
  • click Export, then save the file to your desktop
  • click Back, then Finish to exit ESET Online Scanner.

Don't forget to re-enable your antivirus when finished!
 

Can you tell me if there are any problems and if so, what they are.

Nina

 


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#12 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 09:21 PM

Hi Nina,

 

Fixlog:

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 04-10-2016
Ran by admin (09-10-2016 07:38:50) Run:1
Running from C:\Users\admin\Desktop
Loaded Profiles: admin (Available Profiles: admin & DefaultAppPool)
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-147963221-2690506050-476830512-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-147963221-2690506050-476830512-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-27] (Microsoft Corporation)
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CustomCLSID: HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.27.5\psuser.dll => No File
CustomCLSID: HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.26.9\psuser.dll => No File
Task: {02CA5B98-8FB1-4BFD-93DA-006CBBB4E724} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {390BAD78-261E-4515-AE07-1793D49AA6F9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {3B284F0D-EEB5-4714-9A9D-C4081F7BDAD3} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {3FB78968-1099-48A8-A7E4-CDCFD8B7B2DC} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {496ECCB1-559F-4894-93F8-0E01479E6FE7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {6716136F-C912-4D9E-B669-69C15FAD78AA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {7A1E3FEF-F0D2-4029-BEA7-1FB6274301D0} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {E466C52A-74DC-405D-B550-5F760C4C9D9D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {F24F1816-8E2A-45FA-873F-29C6FF2FC0E2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
EmptyTemp:
*****************
 
"HKLM\SOFTWARE\Policies\Google" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}" => key removed successfully.
HKCR\CLSID\{BB82DE59-BC4C-4172-9AC4-73315F71CFFE} => key not found. 
HKU\S-1-5-21-147963221-2690506050-476830512-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-147963221-2690506050-476830512-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => key removed successfully.
HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found. 
"HKCR\PROTOCOLS\Handler\grooveLocalGWS" => key removed successfully.
"HKCR\CLSID\{88FED34C-F0CA-4636-A375-3CB6248B04CD}" => key removed successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib" => key removed successfully.
"HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}" => key removed successfully.
"HKU\S-1-5-21-147963221-2690506050-476830512-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02CA5B98-8FB1-4BFD-93DA-006CBBB4E724}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02CA5B98-8FB1-4BFD-93DA-006CBBB4E724}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{390BAD78-261E-4515-AE07-1793D49AA6F9}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{390BAD78-261E-4515-AE07-1793D49AA6F9}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3B284F0D-EEB5-4714-9A9D-C4081F7BDAD3}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B284F0D-EEB5-4714-9A9D-C4081F7BDAD3}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3FB78968-1099-48A8-A7E4-CDCFD8B7B2DC}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FB78968-1099-48A8-A7E4-CDCFD8B7B2DC}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{496ECCB1-559F-4894-93F8-0E01479E6FE7}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{496ECCB1-559F-4894-93F8-0E01479E6FE7}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6716136F-C912-4D9E-B669-69C15FAD78AA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6716136F-C912-4D9E-B669-69C15FAD78AA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A1E3FEF-F0D2-4029-BEA7-1FB6274301D0}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A1E3FEF-F0D2-4029-BEA7-1FB6274301D0}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E466C52A-74DC-405D-B550-5F760C4C9D9D}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E466C52A-74DC-405D-B550-5F760C4C9D9D}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F24F1816-8E2A-45FA-873F-29C6FF2FC0E2}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F24F1816-8E2A-45FA-873F-29C6FF2FC0E2}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 3627956 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 18905970 B
Java, Flash, Steam htmlcache => 13528 B
Windows/system/drivers => 407165220 B
Edge => 57239020 B
Chrome => 28250680 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 13824 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
LocalService => 71120 B
NetworkService => 10591174 B
admin => 41410334 B
DefaultAppPool => 6144 B
 
RecycleBin => 55278 B
EmptyTemp: => 541.1 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 07:41:33 ====
 
Working on the next steps.
 
Thanks,
Raman Nallamilli.


#13 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 08 October 2016 - 09:33 PM

Hi Nina,

 

I am getting 404 error when clicked on the link. below screen shot for your review.

 

Thanks,

Raman Nallamilli.



#14 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:51 PM

Posted 09 October 2016 - 03:01 AM

So am I. Don't know why all of a sudden.

 

Try this link.


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#15 rnallamilli

rnallamilli
  • Topic Starter

  • Members
  • 318 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:21 PM

Posted 09 October 2016 - 06:42 AM

Hi Nina,

 

ESET program errored out. Ran twice and it errored out twice. attached screen print for your review.

Also attached ESET parameters for your review.

 

Thanks,

Raman Nallamilli.

 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users